CVE-2026-64089: batman-adv: tt: fix negative last_changeset_len
In the Linux kernel, the following vulnerability has been resolved:
batman-adv: tt: fix negative lastchangesetlen
batadvpivtt::lastchangesetlen len was declared as s16, but the field is never intended to hold a negative value. When a value greater than 32767 is assigned, it wraps to a negative signed integer.
In batadvsendmyttresponse(), lastchangesetlen is temporarily widened to s32. The incorrectly negative s16 value propagates into the s32, causing batadvttpreparetvlvlocaldata() to allocate a full sized buffer but populates only a small portion of it with the collected changeset. All remaining bits are kept uninitialized.
Using an u16 avoids this type confusion and ensures that no (negative) sign extension is performed in batadvsendmyttresponse().
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-64089?
CVE-2026-64089 has a critical severity rating of 9.8 according to CVSS v3.1.
How do I fix CVE-2026-64089?
To fix CVE-2026-64089, ensure that you update to the latest patched version of the Linux kernel.
What impact does CVE-2026-64089 have on the Linux kernel?
CVE-2026-64089 can cause the last_changeset_len field to wrap to a negative value, potentially leading to unexpected behavior.
Which versions of the Linux kernel are affected by CVE-2026-64089?
CVE-2026-64089 affects specific versions of the Linux kernel that include the batman-adv implementation.
Is CVE-2026-64089 exploitable remotely?
Yes, CVE-2026-64089 is considered exploitable remotely as it involves network functionalities within the Linux kernel.